Operation Blockbuster revealed

2016-02-24 Kaspersky

https://securelist.com/operation-blockbuster-revealed/73914/

Thumbnail for Operation Blockbuster revealed

Kaspersky describes Operation Blockbuster research linking malware used in the Sony Pictures attack to a wider Lazarus Group cluster spanning activity back to at least 2009. The report connects campaigns and malware families including Operation Troy, DarkSeoul, Hangman, Wild Positron/Duuzer, Destover, Sconlog, and SSPPMID through code reuse, shared conventions, and overlapping implementation quirks. Technical evidence includes spearphishing with CVE-2015-6585, hard-coded misspelled "Mozillar" user agents, self-delete BAT file generation, password-protected ZIP resources named MYRES, a reused payload password, and sandbox-hostname checks added to evade analysis. The targeting context includes financial institutions, media, manufacturing, Sony Pictures, and South Korean institutions, while metadata such as Korean locale resources and GMT+8/GMT+9 working patterns is presented as technical context rather than definitive attribution.

Related Actors

Related Reports

2025-04-24 • 35% Match
#ThreatNeedle #LPEClient #SIGNBT #AGAMEMNON #Lazarus #Innorix #SyncHole #CrossEX #T1027.013 #T1082 #T1140 #T1071.001 #T1083 #T1057 #T1583.003 #T1583.001 #T1105 #T1620 #T1574.002 #T1135 #T1573.001 #T1190 #T1189 #T1049 #T1573.002 #T1016 #T1087.001 #T1218.011 #T1584.001 #T1574.001 #T1564.004 #T1027.009 #T1569.002 #T1543.003 #T1087.002 #T1570 #T1608.004 #T1547.005 #T1007 #Copperhedge
Shares tag: Lazarus • Same author: Kaspersky
« Back